Noticed:
/routing filter
add action=accept chain=mt-out disabled=no invert-match=no prefix=x.x.x.0/21
add action=discard chain=mt-out disabled=no invert-match=no
If you try advertise x.x.x.0/22 it will get droped even though its inside the x.x.x.0/21 subnet. Not real desireable at all.
Also noticed of you you do a prepend on your incoming filter your routing table takes a lot longer to load.